AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2023-20867.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSUnscoredNo severity score in this snapshot.
EXPLOITATION STATUSCISA known exploitedAdded Jun 23, 2023
RECORD STATUSAwaiting NVD dataModified Jun 23, 2023

Disclosure summary

VMware Tools contains an authentication bypass vulnerability in the vgauth module. A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine. An attacker must have root access over ESXi to exploit this vulnerability.

CISA remediation guidance

Apply updates per vendor instructions.

Original records & references

PUBLISHED 2023-06-23T00:00:00-04:00
MODIFIED 2023-06-23T00:00:00-04:00
INGESTED 2026-10-06T11:42:58-04:00